Previous Topic: Designate a Provisioning Role AdministratorNext Topic: Role-Based Entitlements


Assigning Roles

As a system administrator, you assign admin roles or provisioning roles to users. A user to whom you have assigned a role is called a role member.

You assign admin roles to grant and limit actions that users can take in CA CloudMinder. Users can perform administrative tasks on user accounts, such as changing a password or updating a job title. Different users have different levels of access to these tasks, which is based on their role membership. For example, with one role a user can only update their own personal information, whereas with another role, a user can administer account privileges for all users.

The admin role, or roles, that are assigned to a user determines which tasks the user can perform. A system administrator assigns a role to a user; that role defines a set of tasks that the user can then perform. The tasks in a given role are logically related to one another. For example, the Human Resources Manager role contains tasks to modify the name, address, title, and salary information. In addition, a user can have multiple roles, allowing you to organize efficiently the tasks each user can perform.

You assign provisioning roles to grant users access to accounts in additional applications, such as an email system. Provisioning roles contain account templates. These templates define the attributes that exist in a type of account. For example, an account template for an Exchange account defines attributes such as the size of the mailbox. Account templates also define how user attributes are mapped to accounts.

The following diagram shows the information to understand, and the steps to perform, in assigning roles.

This diagram illustrates the steps required to assign a role to users.

The following topics explain roles in depth and how to assign them to users.

  1. Understand Role-Based Entitlements.
  2. Understand Role Characteristics.
  3. Assign an Admin Role to a User.
  4. Assign a Provisioning Role to a User.
  5. Assign a Role to Multiple Users.